sibsoft records
3 published records for vendor sibsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2019-18952Proof of concept | SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload.sibsoft · xfilesharing · CWE-434 | Critical9.8 | — | 45.4% | Nov 13, 2019 |
36Monitor | CVE-2019-18951Proof of concept | SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.sibsoft · xfilesharing · CWE-22 | High7.5 | — | 19.8% | Nov 13, 2019 |
11Monitor | CVE-2006-1944Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web scsibsoft · communimail | Low2.6 | — | 2.1% | Apr 20, 2006 |
- CVE-2019-1895253Plan
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload.
CriticalCVSS 9.8Proof of conceptEPSS 45%sibsoft · xfilesharingNov 13, 2019
- CVE-2019-1895136Monitor
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
HighCVSS 7.5Proof of conceptEPSS 20%sibsoft · xfilesharingNov 13, 2019
- CVE-2006-194411Monitor
Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web sc
LowCVSS 2.6Proof of conceptEPSS 2%sibsoft · communimailApr 20, 2006